Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Tracking the created files on a specific folder using Deep Security Integrity Monitoring

    • Updated:
    • 18 Nov 2019
    • Product/Version:
    • Deep Security 10.0
    • Deep Security 11.0
    • Deep Security 12.0
    • Platform:
    • N/A
Summary

Use the Integrity Monitoring module of Deep Security to monitor and detect the created files under a specific folder.

Details
Public

To monitor the created files, create a custom rule that targets the directory:

 
This rule might cause high number of alerts if the monitored directory is dynamic. Use it carefully.
  1. On the Deep Security console, go to Policies > Common Objects.
  2. Navigate to Rules > Integrity Monitoring Rules.
  3. Click New and select New Integrity Monitoring Rule.
  4. Go to Content tab.
  5. Choose File for Template.
  6. Enter the path on the Base Directory field.
  7. Enable the Include Sub Directories checkbox.
  8. On the section Include Files With Names Like, input asterisk (*) to match zero or more characters.
  9. Click Apply to save the new rule.

Create custom rule for Integrity Monitoring

Based on the sample above, it will detect any created files under the /test/ directory. The event will look similar to the following:

Created event

Premium
Internal
Rating:
Category:
Configure
Solution Id:
000153959
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.